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Abstract 

Our problem is to evaluate a multi- valued Boolean function F through oracle calls. If F is one-to-one 
and the size of its domain and range is the same, then our problem can be formulated as follows: 
Given an oracle f{a,x) : {0,1}" x {0,1}" {0,1} and a fixed (but hidden) value uq, we wish to 
obtain the value of ao by querying the oracle f{ao,x). Our goal is to minimize the number of such 
oracle calls (the query complexity) using a quantum mechanism. 

Two popular oracles are the EQ-oracle defined as f{a, x) = 1 iff x = a and the IP-oracle defined 
as /(a, x) = a ■ X mod 2. It is also well-known that the query complexity is 0(\/iV) {N = 2") for the 
EQ-oracle while only 0(1) for the IP-oracle. The main purpose of this paper is to fill this gap or to 
investigate what causes this large difference. To do so, we introduce a parameter K as the maximum 
number of I's in a single column of Tf where Tf is the N x N truth-table of the oracle f{a,x). Our 
main result shows that the (quantum) query complexity is heavily governed by this parameter K: (i) 
The query complexity is VI{-\/WJK). (ii) This lower bound is tight in the sense that we can construct 
an explicit oracle whose query complexity is 0{y^ N/K). (Hi) The tight complexity, 6(^ -|- logK), is 
also obtained for the classical case. Thus, the quantum algorithm needs a quadratically less number of 
oracle calls when K is small and this merit becomes larger when K is large, e.g., logK v.s. constant 
when K = cN. 



1 Introduction 



In PI, Ambainis introduced the problem of evaluating a (multi- valued and incompletely specified) 
Boolean function F{xo, . . . ,xn-i) using a quantum mechanism. This problem includes many inter- 
esting specific problems. For example, if we define 



F{xo, . . ■,XN~l) 



{a ii Xa = 1 and xj = for all j / a, 

undefined otherwise. 
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Figure 1: f{a,x) = EQa{x) 



then evaluating this function F is the same as the so-cahed Grover search. Also, if we define 
F(xo, . . . ,XAr_i) 



a \i Xi = a ■ i mod 2 for all < i < 

undefined otherwise, 



then this is the same as the so-called Bernstein- Vazirani problem |S| introduced in ^01- "Quantum 
evaluation" assumes that we can obtain the value of variable Xi only through an oracle 0{i). Since 
both functions are one-to-one, and their domain and range are of the same size, we can formulate the 
problem as follows. 

Let n be an integer > 1 and = 2". Then, given an oracle defined as a function 

/(a,x):{0,irx{0,ir^{0,l} 

such that f{ai,x) ^ f{a2, x) for some x if oi 7^ 02, and a fixed (and hidden) value a, we wish to obtain 
the value a, using the oracle f{a,x). For the Grover search, one can easily see that the definition as 



fia,x) 



1 if X = a, 
otherwise, 



completely specifies the problem. This oracle is sometimes called the EQ oracle and is denoted by 
EQa{x). See Fig. 1 for n = A. As illustrated in this figure, f{a,x) is given by a truth table of size 
N X N, where each row gives the value of the function F of the previous definition. For example, we 
have F(l, 0, . . . , 0) = 0000 from the first row of the table. If the hidden value a is 0010 for example, 
the oracle returns value 1 only when it is queried with x = 0010. For the Bernstein- Vazirani problem, 
the similar definition is given as 

/(a, x) = a ■ X mod 2, 
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Figure 2: /(a, x) = a ■ x = J2i '^i ' mod 2 



which is called the inner product (IP) oracle and denoted by IPa{x). Its truth table for n = 4 is given 
in Fig. 2. (Through this paper, we assume that the domain of the Boolean function F has the same 
size as its range. More general cases, e.g., the size of the range is larger than the domain, will be 
mentioned briefly in the last section.) 

As usual, our interest is in the (quantum) query complexity, i.e., how many oracle calls are needed 
to obtain the hidden value of a. It is well-known that the query complexity for the EQ-oracle is 
e(\/iV)[Sl|SliniI71llIT3], while only 0(1) for the IP-oracle H El. Why does such a big difference exist 
between the EQ and IP oracles? The difference might become clearer if we compare their truth tables 
given in Figs. 1 and 2. One can immediately see that the table for IPa is well-balanced in terms of the 
numbers of O's and I's, but quite unbalanced for EQa- The natural consequence is that there should be 
intermediate oracles between those extreme ones for which the query complexity is also intermediate 
between 0(\/iV) and 0(1). Furthermore these intermediate oracles could be characterized by some 
parameter in such a way that the query complexity heavily depends upon this parameter value and 
both EQa and IPa are obtained as special cases. The main purpose of this paper is to show that this 
conjecture is true. 

Our Contribution. Let Tj be the truth-table of an oracle f{a,x) like the ones given in Figs. 1 
and 2. We can assume without loss of generality that the number of I's is less than or equal to the 
number of O's in each column of Tf. Let ^i{Tf) denote the number of I's (< N/2) in the i-th column 
of Tf and i^{Tf) = max7^j(T/-). Then we can show that this single parameter #{Tf) plays a key 

i 

role, namely: (i) Let f{a,x) be any oracle and K = ^(Tf). Then the query complexity of the search 
problem for f(a,x) is il{y^N/ K). For this result, we extend the main theorem in P|. Although the 
extension may seem moderate in terms of the statement, it actually increases a lot of usefulness of the 
theorem, (ii) This lower bound is tight in the sense that we can construct an explicit oracle whose 
query complexity is 0{y/N/ K). This oracle again includes both EQ and IP oracles as special cases. 
{in) The tight complexity, ©(^ + logK), is also obtained for the classical case. Thus, the quantum 
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algorithm needs a quadratically less number of oracle calls when K is small and the merit is even 
larger when K is large, e.g., log-ftT v.s. constant when K = cN. 

It should be noted that our (tight) bound @{\/ N/K) looks similar to the tight bound of the 
-RT-solution Grover searchjT]. This paper also examines the similarity and dissimilarity between our 
problem and the multi-solution (MS) Grover: In our notation, MS-Grover is the problem for obtaining, 
for a fixed oracle /(a, x) and a fixed value a both of which are hidden, the value b £ {0, 1}" such that 
f{a,b) = 1. (i) There is an oracle for which our problem needs r2(\/iV) oracle calls while MS- 
Grover 0(1) ones, (u) The complexity of the two problems is approximately the same if the oracle 
is "balanced" (defined later) and K < N'^^^. Intuitively our problem seems at least as hard as MS- 
Grover, but we can also show the existence of an oracle which objects this intuition. 

Related Results. Query complexity has constantly been one of the central topics in quantum 
computation, especially in proving lower bounds of quantum algorithms with oracles. Generally 
speaking, there are two popular techniques to derive quantum lower bounds, i.e., polynomials and 
adversary methods. The polynomials method was firstly introduced in quantum computation by 

who borrowed the idea from the classical polynomial method. For example, it was shown that 
for bounded error cases, evaluations of AND and OR functions need G(\/iV) number of queries, 
while parity and majority functions at least N/2 and 6(A^), respectively. Recently, used the 

polynomials method to show the lower bounds for collisions and element distinctness problems. 

The adversary method was used in E] j although their method resembles the classical one and 
for that reason it is called the hybrid method. Their method can be used, for example, to show the 
lower bound of the Grover Search. Recently, Ambainis introduced a quite general method, which 
is known as quantum adversary argument, for obtaining lower bounds of various problems, e.g., the 
Grover Search, AND of ORs and inverting a permutation^. Some lower bounds are easier to obtain 
using the quantum adversary method than the polynomials one. The most recent result is by jlj who 
extended to establish a lower bound of r2(\/iV) on the bounded-error quantum query complexity 
of read-once Boolean functions. 



2 Quantum Lower Bounds 

Our lower bound result is related to the main theorem of 0. In this section, we give a slight extension 
of the Ambainis' result, from which our result immediately follows. We first review Theorem 5.1 in 
(Note that the statement uses the original definition of our problem.) 

Proposition 1 Let F{xo, . . . ,xn-i) be a function of N {0, 1} — valued variables and X,Y be two sets 
of inputs such that F{x) ^ F[y) if x £ X and y €zY . Let R C X x Y be such that 

1. For every x £ X, there exist at least m different y £Y such that {x,y) G R. 

2. For every y £Y , there exist at least m' different x € X such that (x, y) G R. 

3. For every x and i G {0, . . . , — 1}, there are at most I different y & Y such that {x,y) £ R and 
Xi / yi. 

4- For every y and i G {0, . . . ,N — 1}, there are at most I' different x € X such that {x, y) £ R and 
Xij^yi. 

Then, any quantum algorithm computing F uses r2(w ^^^jp^) queries. 
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Our extension is due to the fact that the selection of the two sets, X and y, may not necessarily 
be unique but may alter for each column. 

Theorem 1 Let F{xq, . . . ,xm-i) be a function of N {0,1} — valued variables and Xi,Yi, for i £ 
{0, . . . , — 1}, be sets of inputs such that F{x) ^ F{y) if x £ Xi and y £ Yi, and Xq\JYq = 
■ ■ ■ = Xn^i U y/v-i- Let Ri C Xi X Yi be such that 

1. For every x G Xi, there exist at least m different y £Yi such that {x,y) G Ri. 

2. For every y £Yi, there exist at least m' different x £ Xi such that {x,y) £ Ri. 

3. For every x and j £ {0, . . . , — 1}, there are at most I different y £ Yi such that {x,y) £ 
i?o U ■ • • U Rn-1 o,nd Xj 7^ yj. 

4. For every y and j £ {0, . . . , — 1}, there are at most I' different x £ Xi such that {x,y) £ 
i?o U • • • U Rn-1 dnd Xj 7^ yj. 

Then, any quantum algorithm computing F uses VL{^J^^-) queries. 

Proof. Omitted since it is enough to make word-to- word replaces in the original proof of |3] ■ d 

Now our lower-bound result is almost immediate. Recall that our oracle is defined by f{a,x) : 
{0, !}"■ X {0, l}" {0, 1}. If we use the notation F, its range is {0, 1}" and for any x,y £ {0, 1}^ 
such that X ^ y, it is guaranteed that F{x) 7^ F{y) if they are defined. 

Corollary 1 Let f be an oracle such that i^{Tf) = K . Then any quantum algorithm that computes a 
target a with probability 1 — e needs N/K) oracle calls for some fixed e < 1/2. 



Proof. Recall that K < N/2. So we can select Xi and Yi of Theorem 1 such that \Xi\ = |Yi| = N/2 
and if Xj = 1 then x £ Xi (i.e., all Yi do not include y such that yi = 1). Now it is not hard to see 
that we can set m = m' = I = N/2 and I' = K. Hence, Theorem 1 implies that the query complexity 




Note that Proposition 1 is, if we use it as it is, not so powerful; we cannot prove the lower bound of 
the Grover search for instance. In [^1, Ambainis made a different kind of extension against Proposition 
1 to prove several lower bounds including Grover's. This extension is quite powerful but does not seem 
appropriate for our purpose. Our extension is also powerful, which will be used later to prove other 
lower bounds. 



3 Quantum Upper Bounds 



In this section, we show that there exists a specific oracle whose query complexity is 0{^J N/K). 
The oracle intuitively works partly as the EQ-oracle and partly as the IP-oracle and therefore we 
call it a hybrid oracle. The hybrid oracle with a parameter 1 < k < n, denoted by hk[a,x), is 
defined as follows {k indicates the size of its IP-part): Let a = (oi, 02, . . . , a„_fc, On-k+i-, ■ ■ ■ , O'n) and 
X = {xi,X2, . . . ,Xn-k,Xn-k+i, ■ ■ ■,Xn). Then hk{a,x) = 1 iff (i) (ai, ...,a„_fc) = (xi, ...,x„_fc) and (ii) 
(on-k+i, ■■■,0'n) • {xn-k+1, ■■■,Xn) = (mod 2). Fig. 3 shows /i2 for n = 4. One can see that the small 
4x4 matrix is the negation of the IP-oracle. 
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Figure 3: The hybrid oracle with n = 4 and k = 2 



Theorem 2 There exists a quantum algorithm to find a target a using 0{V¥^) calls ofhk. 



Proof. We combine Grover search [7] with BV algorithm [H] to find a target a using the hybrid 
oracle hk- At first, we can determine the first n — k bits of a. Fixing the last k bits to |0), we apply 
Grover search using oracle hk for the first n — k bits to determine ai, a^-k- It should be noted that 
hk{a, (ai, . . . ,a„_fc,0, ... ,0)) = 1 and /ifc(a, (xi, . . . ,Xn_fc,0, ... ,0)) = for any xi, ^ ai, ...,afc - 

Next, we apply BV algorithm to determine the remaining k bits. This algorithm requires 0{y/N/K) 
queries for Grover search and 0(1) queries for BV algorithm. □ 



Corollary 2 There exists an oracle f such that i^{Tf) = K and its query complexity is 0{^JN/K). 



Thus Corollary 1 is tight in the sense that we cannot improve it in general. Note that both 
Corollaries 1 and 2 hold for the EQ- and IP-oracles. We can also prove the same upper bound, 
0{y/ N/K), for a more general class of oracles if we restrict the value of K. An oracle / is said to be 
balanced if all columns and all rows have the same number of I's. 

Theorem 3 For a balanced oracle f{a,x) with K < N^''^ , there exists a quantum algorithm to find a 
target a using 0{^J N / K) queries of f . 



Proof. Since f{a,x) is balanced, each row and each column of Ty has exactly K I's. Our algorithm 
consists of two parts; the first part is quantum and the second part classical: The first part of the 
algorithm is to reduce the size of the search space from N to K which is achieved by using (multi- 
solution) Grover search. It first finds an x such that f{a,x) = 1. Since each row of Ty has K I's, the 



6 



query complexity of this first part is 0{-\/ N/K). Also since each column has K I's, the number of a 
satisfying f{a,x) = 1 for a particular x is exactly K. Now, let a subset R = {a\f{a,x) = 1}, which 
includes the candidates of a. 

The second part of the algorithm is to repeatedly choose an index y such that 3a, b e R where 
f{a,y) 7^ f{b, y). Clearly, unless |-R| = 1, there must exist such y, which can reduce the number of 
the candidates at least by one. More formally, let the query's result for such y is m G {0, 1}. Then, 
we can substitute RCi {b\f{b,y) = m} for R, by which \R\ decreases at least by one. The total query 
complexity is thus 0{^/nJK) + K, which is 0{^fNjK) for K < N^^. □ 



4 Relation to Grover Upper and Lower Bounds 

As described in Section 1, our problem is closely related to MS-Grover. However, there exist some 
gaps between those two problems. In this section, we show some explicit oracles such that the query 
complexities of those two problems are quite different. The following theorem shows the oracle such 
that our problem is harder than MS-Grover. 

Theorem 4 There is an oracle f such that the query complexity of our search problem is ^l{^/N) and 
that of MS-Grover is 0{1). 

Proof. Consider an oracle / whose truth-table is such that the upper left and the lower right of the 
table is exactly the same as the EQ-oracle, and all the elements of the upper right and the lower left 
of the table are I's. (See Fig. 4 for A'^ = 16.) Then it is obvious that we need only 0{1) queries to find 
X such that /(a, x) = 1 since the number of such x is so large that even choosing x randomly suffices. 
On the other hand, we can show the hardness of finding a for this oracle by Theorem 1. We select Xi 
and Yi of Theorem 1 such that Xj U 1^ is equal to the upper half of the truth-table, \Xi\ = \Yi\ = A/4 
and if Xj = 1 then x G Xi for i < N/2. Then, one can easily see that m = m! = I = N/A and I' = 1. 
Therefore, we need r2(-\/A) queries to find a. □ 

Thus our problem is much harder than MS-Grover in this particular oracle. It is also true, as shown 
in the previous section, that our problem has approximately the same query complexity as MS-Grover 

for balanced oracles with K < N'^^^. Then, is there any oracle for which MS-Grover is harder than 
our problem? We have no formal answer to this question, but the following example suggests that the 
answer is probably yes: Let /P^ be an oracle which is exactly the same as I Pa except that /(O, z) = 1 
for some single z (recall that f{0,z) = in I Pa). Then, if we simply use the Grover search, it needs 
\/A queries when a = 0. (Recall that we assumed that MS-Grover does not have any information 
on the oracle table Tf so that this seems to be the best we can do.) In contrast, if we use the BV 
algorithm, then we can get the value of a with high probability since I Pa is so close to I Pa- (It is easy 
to compute the success probability, which may be omitted.) 

5 Classical Lower and Upper Bounds 

We first give the classical lower bound and then prove the matching upper bound using the same 
oracle given in the previous section. 
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Figure 4: A truth-table where our problem is harder than MS-Grover 



Theorem 5 Suppose that f is an arbitrary oracle such that i^iTf) is K . Then any classical algorithm 
needs at least [^J + [log K\ — 2 oracle calls to obtain a target in the worst case. 

Proof. The following proof is due to the standard adversary argument. Let A be any classical algo- 
rithm using the oracle /. Suppose that the target is a G {0, 1}". Then the execution of A is described 
as follows: (i) In the first round, A calls the oracle with the predetermined value xq and the oracle 
answers with = /(a, xq). (ii) In the second round, A calls the oracle with value xi, which is de- 
termined by do and the oracle answers with di = f{a,xi). (iii) In the (i + l)-st round, A calls the 
oracle with Xj which is determined by do, di, di-i and the oracle answers with di = f{a, Xi). (iv) In 
the m-th round A outputs the target a which is determined by do, tii, (i„j_i and stops. Thus, the 
execution of A is completely determined by the sequence (do, di, d„j_i) which is denoted by A{a). 
(Obviously, if we fix a specific target a, then A{a) is uniquely determined). 

Let TO-o = \_N/K\ + [logi^J — 3 and suppose that A halts in the mo-th round. We compute the 
sequence (co, ci, . . . , Cmo), Ci G {0, 1}, and another sequence (Lo, Li, . . . , L^^), Lj C {a\a G {0, 1}"}, 
as follows (note that cq,. . . ,Cmo are similar to do, ...,dm-i above and are chosen by the adversary): 
(i) Lq = {0, 1}". (ii) Suppose that we have already computed Lq, Li, and cq, Cj_i. Let Xj be the 
value with which A calls the oracle in the (i + l)-st round. (Recall that Xj is determined by cq, Q-i.) 
Let L° = {s\ f{s, Xi) = 0} and = {s\ f{s, Xi) = 1}. Then if \Li n L°| > \Li n then we set q = 
and Lj_|_i = -L, fl L°. Otherwise, i.e., if \Li n L°| < |Lj PI L^\, then we set Cj = 1 and Lj+i = Lj fl L^. 

Now we can make the following two claims. 

Claim 1. \L„i„\ > 2. (Reason: Note that \Lq\ = N and the size of Lj decreases as i increases. 
By the construction of Li, one can see that until |Lj| becomes 2K, its size decreases additively by at 
most if in a single round and after that it decreases multiplically at most one half. The claim then 
follows by a simple calculation.) 
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Claim 2. If a G Lmo, then (cq, . . . , Cmo) = A{a). (Reason: Obvious since a G Lq H Li n • • • H Lmo-) 

Now it follows that there are two different ai and 02 in L^q such that ^(oi) = A(a2) by Claims 1 
and 2. Therefore j4 outputs the same answer for two different targets oi and 02, a contradiction. □ 

Next, we consider classical upper bounds for the hybrid oracle discussed in Section 3. Recall that 
K = 2^ 

Theorem 6 There exists a classical algorithm to find a target a using 0{^ + logK) calls ofhk. 

Proof. The algorithm consists of an exhaustive and a binary search. First, we determine the first 
n — k bits by fixing the last k bits to all O's and using exhaustive search. Second, we determine the 
last k bits by using binary search. This algorithm needs 2"'~^{= ^) queries in the exhaustive search, 
and 0{k){= 0(logK)) queries in the binary search. Therefore, the total complexity of this algorithm 
isO(2"-'= + fc)(=0(f + logK)). □ 



6 Concluding Remarks 

We have assumed through this paper that the size of Tf is N x N, i.e., the size of the domain and the 
size of the range of the Boolean function F are the same. This restriction can of course be removed. 

f N \ 

For example, consider the ( ^ j ^ table Tf which includes every string y consisting oi K I's and 
(A^ — K) O's in its rows. One can see this is exactly the same as the X-solution Grover search if our 
answer is to obtain an x such that f{a,x) = 1 and its complexity is Q{\J^)- Recall again that our 
present problem is different, i.e., we need to obtain a. We can also use Theorem 1, which implies 
(details are omitted) a lower bound of ^^(y'^)- This lower bound is the same as the lower bound 
of MS-Grover and seems too weak as a lower bound of obtaining a. Fortunately it is not hard to 
improve this lower bound up to 0(\/]V) if K = cN: By selecting K rows appropriately, we can obtain 
a smaller table which is similar to the table given in Fig. 4. Nevertheless, this \/iV lower bound still 
seems weak; the real bound is probably much larger than \/iV- To obtain such a "/luge" lower bound 
for natural oracles (,3^ has obtained one for an artificial oracle) should be interesting future work. 

Another future direction is to find a different parameter which can control upper bounds of the 
query complexity of evaluating functions. Note that the Hamming distance between two rows of Tf is 
0(1) for the EQ-oracle and N/2 for the IP-oracle. This fact might be a good hint for this direction. 
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